PT-2026-61226 · Linux · Linux

CVE-2026-63909

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: OOB read regression in smb check perm dacl() ACE-walk loops
Commit d07b26f39246 ("ksmbd: require minimum ACE size in smb check perm dacl()") introduced a transposed bounds check:
if (offsetof(struct smb ace, sid) + aces size < CIFS SID BASE SIZE)
Since offsetof(..sid) is 8 and CIFS SID BASE SIZE is 8, this evaluates to aces size < 0. Because aces size is always non-negative, this check becomes dead code and never breaks the loop.
Worse, that commit removed the old 4-byte guard, meaning the loop now reads ace->size (offset 2) even when aces size is 0-3 bytes. This re-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation during subsequent SMB2 CREATE operations.
Fix this by properly transposing the comparison to require at least 16 bytes (8-byte offset + 8-byte SID base), matching the correct form used in smb inherit dacl().

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-63909

Produtos afetados

Linux